CVE-2023-21414
NCC Group has found a flaw during the annual internal penetration test ordered by Axis Communications. The protection for device tampering (commonly known as Secure Boot) contains a flaw which provides an opportunity for a sophisticated attack to bypass this protection. Axis has released patched AXIS OS versions for the highlighted flaw. Please refer to the Axis security advisory for more information and solution.
Published:Oct 16, 2023
Last Modified:Nov 21, 2024
EPS:Oct 16, 2023
EPSS Score:0.00012
CVSS Score:7.1
Affected Products
Vendor
Product
Action
Vendor
Axis
Product
A8207-ve Mk Ii
Axis
A8207-ve Mk Ii
Vendor
Axis
Product
Axis Os
Axis
Axis Os
Vendor
Axis
Product
M3215
Axis
M3215
Vendor
Axis
Product
M3216
Axis
M3216
Vendor
Axis
Product
M4317-plve
Axis
M4317-plve
Vendor
Axis
Product
M4318-plve
Axis
M4318-plve
Vendor
Axis
Product
M4327-p
Axis
M4327-p
Vendor
Axis
Product
M4328-p
Axis
M4328-p
Vendor
Axis
Product
P1467-le
Axis
P1467-le
Vendor
Axis
Product
P1468-le
Axis
P1468-le
Vendor
Axis
Product
P1468-xle
Axis
P1468-xle
Vendor
Axis
Product
P3265-lv
Axis
P3265-lv
Vendor
Axis
Product
P3265-lve
Axis
P3265-lve
Vendor
Axis
Product
P3265-v
Axis
P3265-v
Vendor
Axis
Product
P3267-lv
Axis
P3267-lv
Vendor
Axis
Product
P3267-lve
Axis
P3267-lve
Vendor
Axis
Product
P3268-lv
Axis
P3268-lv
Vendor
Axis
Product
P3268-lve
Axis
P3268-lve
Vendor
Axis
Product
P3827-pve
Axis
P3827-pve
Vendor
Axis
Product
P4705-plve
Axis
P4705-plve
Vendor
Axis
Product
P4707-plve
Axis
P4707-plve
Vendor
Axis
Product
Q1656
Axis
Q1656
Vendor
Axis
Product
Q1656-b
Axis
Q1656-b
Vendor
Axis
Product
Q1656-be
Axis
Q1656-be
Vendor
Axis
Product
Q1656-ble
Axis
Q1656-ble
Vendor
Axis
Product
Q1656-dle
Axis
Q1656-dle
Vendor
Axis
Product
Q1656-le
Axis
Q1656-le
Vendor
Axis
Product
Q1961-te
Axis
Q1961-te
Vendor
Axis
Product
Q2101-te
Axis
Q2101-te
Vendor
Axis
Product
Q3527-lve
Axis
Q3527-lve
Vendor
Axis
Product
Q3536-lve
Axis
Q3536-lve
Vendor
Axis
Product
Q3538-lve
Axis
Q3538-lve
Vendor
Axis
Product
Q3626-ve
Axis
Q3626-ve
Vendor
Axis
Product
Q3628-ve
Axis
Q3628-ve
Vendor
Axis
Product
Xfq1656
Axis
Xfq1656
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
No CAPEC recorded yet
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
